Skip to content

Commit fd68f4b

Browse files
Sync Collecting Fix Commits: Tue Aug 11 06:03:56 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent 4807456 commit fd68f4b

6 files changed

Lines changed: 149 additions & 24 deletions

data/fix-commits/advisory-database-b78f1d41.json

Lines changed: 29 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,35 @@
11
{
22
"vcs_url": "https://github.com/github/advisory-database",
33
"vulnerabilities": {
4+
"GHSA-6V23-65FJ-8G7C": {
5+
"e0c7c9bae9bc6901f61717979fab356b72922558": "Publish Advisories\n\nGHSA-6v23-65fj-8g7c\nGHSA-8vgw-m5fh-hwg3\nGHSA-9f5f-7wxj-73g8\nGHSA-f3xx-69mr-6rx6\nGHSA-gcr6-hgjr-2h8p\nGHSA-hgvh-9fpj-948w\nGHSA-vhwm-f68v-4vg9"
6+
},
7+
"GHSA-8VGW-M5FH-HWG3": {
8+
"e0c7c9bae9bc6901f61717979fab356b72922558": "Publish Advisories\n\nGHSA-6v23-65fj-8g7c\nGHSA-8vgw-m5fh-hwg3\nGHSA-9f5f-7wxj-73g8\nGHSA-f3xx-69mr-6rx6\nGHSA-gcr6-hgjr-2h8p\nGHSA-hgvh-9fpj-948w\nGHSA-vhwm-f68v-4vg9"
9+
},
10+
"GHSA-9F5F-7WXJ-73G8": {
11+
"e0c7c9bae9bc6901f61717979fab356b72922558": "Publish Advisories\n\nGHSA-6v23-65fj-8g7c\nGHSA-8vgw-m5fh-hwg3\nGHSA-9f5f-7wxj-73g8\nGHSA-f3xx-69mr-6rx6\nGHSA-gcr6-hgjr-2h8p\nGHSA-hgvh-9fpj-948w\nGHSA-vhwm-f68v-4vg9"
12+
},
13+
"GHSA-F3XX-69MR-6RX6": {
14+
"e0c7c9bae9bc6901f61717979fab356b72922558": "Publish Advisories\n\nGHSA-6v23-65fj-8g7c\nGHSA-8vgw-m5fh-hwg3\nGHSA-9f5f-7wxj-73g8\nGHSA-f3xx-69mr-6rx6\nGHSA-gcr6-hgjr-2h8p\nGHSA-hgvh-9fpj-948w\nGHSA-vhwm-f68v-4vg9"
15+
},
16+
"GHSA-GCR6-HGJR-2H8P": {
17+
"e0c7c9bae9bc6901f61717979fab356b72922558": "Publish Advisories\n\nGHSA-6v23-65fj-8g7c\nGHSA-8vgw-m5fh-hwg3\nGHSA-9f5f-7wxj-73g8\nGHSA-f3xx-69mr-6rx6\nGHSA-gcr6-hgjr-2h8p\nGHSA-hgvh-9fpj-948w\nGHSA-vhwm-f68v-4vg9"
18+
},
19+
"GHSA-HGVH-9FPJ-948W": {
20+
"e0c7c9bae9bc6901f61717979fab356b72922558": "Publish Advisories\n\nGHSA-6v23-65fj-8g7c\nGHSA-8vgw-m5fh-hwg3\nGHSA-9f5f-7wxj-73g8\nGHSA-f3xx-69mr-6rx6\nGHSA-gcr6-hgjr-2h8p\nGHSA-hgvh-9fpj-948w\nGHSA-vhwm-f68v-4vg9"
21+
},
22+
"GHSA-VHWM-F68V-4VG9": {
23+
"e0c7c9bae9bc6901f61717979fab356b72922558": "Publish Advisories\n\nGHSA-6v23-65fj-8g7c\nGHSA-8vgw-m5fh-hwg3\nGHSA-9f5f-7wxj-73g8\nGHSA-f3xx-69mr-6rx6\nGHSA-gcr6-hgjr-2h8p\nGHSA-hgvh-9fpj-948w\nGHSA-vhwm-f68v-4vg9"
24+
},
25+
"GHSA-355H-QMC2-WPWF": {
26+
"ab51be468d8829b7676d5bf564b7b0bc7bd65714": "Improve GHSA-355h-qmc2-wpwf",
27+
"1cee5d8e4211d69170634e60c255a393d17e5456": "Publish Advisories\n\nGHSA-2hx3-vp6r-mg3f\nGHSA-355h-qmc2-wpwf\nGHSA-66hx-chf7-3332\nGHSA-fj52-5g4h-gmq8\nGHSA-hv4r-mvr4-25vw"
28+
},
29+
"GHSA-XG43-5579-QW6V": {
30+
"4bda18f598ef3ca0ce4d719e8dc6dea70666783d": "Improve GHSA-xg43-5579-qw6v",
31+
"5db74df4398057685d929582db73d089fd04717a": "Publish Advisories\n\nGHSA-q3g8-rjrx-59ph\nGHSA-xg43-5579-qw6v\nGHSA-q3g8-rjrx-59ph"
32+
},
433
"GHSA-JX74-CQJV-2C67": {
534
"71fc59e86369b6ca56cae5875bd755903409681d": "Publish GHSA-jx74-cqjv-2c67",
635
"4ac579cf75502357fa92d0b50d1eff45200d078a": "Merge pull request #8899 from github/BarakSrour-GHSA-jx74-cqjv-2c67",
@@ -7468,9 +7497,6 @@
74687497
"GHSA-Q3G8-RJRX-59PH": {
74697498
"5db74df4398057685d929582db73d089fd04717a": "Publish Advisories\n\nGHSA-q3g8-rjrx-59ph\nGHSA-xg43-5579-qw6v\nGHSA-q3g8-rjrx-59ph"
74707499
},
7471-
"GHSA-XG43-5579-QW6V": {
7472-
"5db74df4398057685d929582db73d089fd04717a": "Publish Advisories\n\nGHSA-q3g8-rjrx-59ph\nGHSA-xg43-5579-qw6v\nGHSA-q3g8-rjrx-59ph"
7473-
},
74747500
"GHSA-6F5R-5672-72J7": {
74757501
"37f957452977bca6f94d9652f44316ca0623afcc": "Publish GHSA-6f5r-5672-72j7"
74767502
},
@@ -31979,9 +32005,6 @@
3197932005
"GHSA-GCJ8-76P4-G2FQ": {
3198032006
"fcd705b9491725715696bdf47792ebc545bb8298": "Publish Advisories\n\nGHSA-2x79-gwq3-vxxm\nGHSA-fgmx-xfp3-w28p\nGHSA-g4vj-cjjj-v7hg\nGHSA-gcj8-76p4-g2fq\nGHSA-gcj8-76p4-g2fq"
3198132007
},
31982-
"GHSA-355H-QMC2-WPWF": {
31983-
"1cee5d8e4211d69170634e60c255a393d17e5456": "Publish Advisories\n\nGHSA-2hx3-vp6r-mg3f\nGHSA-355h-qmc2-wpwf\nGHSA-66hx-chf7-3332\nGHSA-fj52-5g4h-gmq8\nGHSA-hv4r-mvr4-25vw"
31984-
},
3198532008
"GHSA-66HX-CHF7-3332": {
3198632009
"1cee5d8e4211d69170634e60c255a393d17e5456": "Publish Advisories\n\nGHSA-2hx3-vp6r-mg3f\nGHSA-355h-qmc2-wpwf\nGHSA-66hx-chf7-3332\nGHSA-fj52-5g4h-gmq8\nGHSA-hv4r-mvr4-25vw"
3198732010
},

data/fix-commits/cpython-cd1cb5b5.json

Lines changed: 8 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,14 @@
11
{
22
"vcs_url": "https://github.com/python/cpython",
33
"vulnerabilities": {
4+
"CVE-2026-12003": {
5+
"872038377db2e170e0e140b5f8aaedf636b3fbf5": "[3.11] gh-151544: Fixes CVE-2026-12003 by removing the fallback to %VPATH%/Modules/Setup.local for discovering sources in getpath.py (GH-151545) (#151568)\n\ngh-151544: Fixes CVE-2026-12003 by removing the fallback to %VPATH%/Modules/Setup.local for discovering sources in getpath.py (GH-151545)\n(cherry picked from commit 9e863fab283eddca9c2a8f9d1ee30f4dc243e314)\n\nCo-authored-by: Steve Dower <steve.dower@python.org>",
6+
"03ab7b44788bfd6b8927e16bcdbd025aa08dce06": "[3.12] gh-151544: Fixes CVE-2026-12003 by removing the fallback to %VPATH%/Modules/Setup.local for discovering sources in getpath.py (GH-151545) (#151567)\n\ngh-151544: Fixes CVE-2026-12003 by removing the fallback to %VPATH%/Modules/Setup.local for discovering sources in getpath.py (GH-151545)\n(cherry picked from commit 9e863fab283eddca9c2a8f9d1ee30f4dc243e314)\n\nCo-authored-by: Steve Dower <steve.dower@python.org>",
7+
"16c40f944b7bff724a403cf4902763d095bb4b2a": "gh-151544: Fixes CVE-2026-12003 by removing the fallback to %VPATH%/Modules/Setup.local for discovering sources in getpath.py (GH-151928)",
8+
"b93d6d3399adbd3a5037b6b92fc3587c85ac5d56": "[3.14] gh-151544: Fixes CVE-2026-12003 by removing the fallback to %VPATH%/Modules/Setup.local for discovering sources in getpath.py (GH-151545)",
9+
"a86de0bc236fbb9452f98998fc8437e9fca35700": "[3.15] gh-151544: Fixes CVE-2026-12003 by removing the fallback to %VPATH%/Modules/Setup.local for discovering sources in getpath.py (GH-151545)\n\n(cherry picked from commit 9e863fab283eddca9c2a8f9d1ee30f4dc243e314)\n\nCo-authored-by: Steve Dower <steve.dower@python.org>",
10+
"9e863fab283eddca9c2a8f9d1ee30f4dc243e314": "gh-151544: Fixes CVE-2026-12003 by removing the fallback to %VPATH%/Modules/Setup.local for discovering sources in getpath.py (GH-151545)"
11+
},
412
"CVE-2021-3737": {
513
"a51c52062a60bbf7184634f768e9c3ae54cec4e7": "[3.12] gh-150743: Limit trailer lines and interim responses read by http.client (GH-150749) (#152527)\n\n[3.14] gh-150743: Limit trailer lines and interim responses read by http.client (GH-150749)\n\nhttp.client read chunked-response trailer lines and skipped interim (1xx)\nresponses in unbounded loops, so a server streaming either forever would\nhang the client even with a socket timeout set (data keeps arriving, so\nthe timeout never fires).\n\nTrailer lines are now limited to max_response_headers (100 by default)\nand interim responses to 100; HTTPException is raised past either limit.\n\nFollow-up to gh-88188 for CVE-2021-3737, which bounded header lines\nwithin an interim response but not these two sibling loops.\n(cherry picked from commit 84badb77f5bb26e51d9a5c478d0e3bfe7ab6eb6f)\n\nCo-authored-by: Gregory P. Smith <68491+gpshead@users.noreply.github.com>\n\n---\n\nThis issue was reported to us via [GHSA-w4q2-g22w-6fr4](https://github.com/python/cpython/security/advisories/GHSA-w4q2-g22w-6fr4)\n\nCo-authored-by: Gregory P. Smith <68491+gpshead@users.noreply.github.com>",
614
"d804d2817b58c8a637d34dac53114f1a11f50cc5": "[3.13] gh-150743: Limit trailer lines and interim responses read by http.client (GH-150749) (#152526)\n\nhttp.client read chunked-response trailer lines and skipped interim (1xx)\nresponses in unbounded loops, so a server streaming either forever would\nhang the client even with a socket timeout set (data keeps arriving, so\nthe timeout never fires).\n\nTrailer lines are now limited to max_response_headers (100 by default)\nand interim responses to 100; HTTPException is raised past either limit.\n\nFollow-up to gh-88188 for CVE-2021-3737, which bounded header lines\nwithin an interim response but not these two sibling loops.\n(cherry picked from commit 84badb77f5bb26e51d9a5c478d0e3bfe7ab6eb6f)\n\nCo-authored-by: Gregory P. Smith <68491+gpshead@users.noreply.github.com>\n\n---\n\nThis issue was reported to us via [GHSA-w4q2-g22w-6fr4](https://github.com/python/cpython/security/advisories/GHSA-w4q2-g22w-6fr4)\n\nCo-authored-by: Gregory P. Smith <68491+gpshead@users.noreply.github.com>",
@@ -15,13 +23,6 @@
1523
"84badb77f5bb26e51d9a5c478d0e3bfe7ab6eb6f": "[3.14] gh-150743: Limit trailer lines and interim responses read by http.client (GH-150749)\n\nhttp.client read chunked-response trailer lines and skipped interim (1xx)\nresponses in unbounded loops, so a server streaming either forever would\nhang the client even with a socket timeout set (data keeps arriving, so\nthe timeout never fires).\n\nTrailer lines are now limited to max_response_headers (100 by default)\nand interim responses to 100; HTTPException is raised past either limit.\n\nFollow-up to gh-88188 for CVE-2021-3737, which bounded header lines\nwithin an interim response but not these two sibling loops.\n\n---\n\nThis issue was reported to us via [GHSA-w4q2-g22w-6fr4](https://github.com/python/cpython/security/advisories/GHSA-w4q2-g22w-6fr4)",
1624
"41cc78a7a47fe584e2c2899737fec877d61ae331": "gh-150743: Limit trailer lines and interim responses read by http.client (GH-150741)\n\nhttp.client read chunked-response trailer lines and skipped interim (1xx)\nresponses in unbounded loops, so a server streaming either forever would\nhang the client even with a socket timeout set (data keeps arriving, so\nthe timeout never fires).\n\nTrailer lines are now limited to max_response_headers (100 by default)\nand interim responses to 100; HTTPException is raised past either limit.\n\nFollow-up to gh-88188 for CVE-2021-3737, which bounded header lines\nwithin an interim response but not these two sibling loops.\n\n---\n\nThis issue was reported to us via [GHSA-w4q2-g22w-6fr4](https://github.com/python/cpython/security/advisories/GHSA-w4q2-g22w-6fr4) and was determined not to be high enough severity to handle privately."
1725
},
18-
"CVE-2026-12003": {
19-
"03ab7b44788bfd6b8927e16bcdbd025aa08dce06": "[3.12] gh-151544: Fixes CVE-2026-12003 by removing the fallback to %VPATH%/Modules/Setup.local for discovering sources in getpath.py (GH-151545) (#151567)\n\ngh-151544: Fixes CVE-2026-12003 by removing the fallback to %VPATH%/Modules/Setup.local for discovering sources in getpath.py (GH-151545)\n(cherry picked from commit 9e863fab283eddca9c2a8f9d1ee30f4dc243e314)\n\nCo-authored-by: Steve Dower <steve.dower@python.org>",
20-
"16c40f944b7bff724a403cf4902763d095bb4b2a": "gh-151544: Fixes CVE-2026-12003 by removing the fallback to %VPATH%/Modules/Setup.local for discovering sources in getpath.py (GH-151928)",
21-
"b93d6d3399adbd3a5037b6b92fc3587c85ac5d56": "[3.14] gh-151544: Fixes CVE-2026-12003 by removing the fallback to %VPATH%/Modules/Setup.local for discovering sources in getpath.py (GH-151545)",
22-
"a86de0bc236fbb9452f98998fc8437e9fca35700": "[3.15] gh-151544: Fixes CVE-2026-12003 by removing the fallback to %VPATH%/Modules/Setup.local for discovering sources in getpath.py (GH-151545)\n\n(cherry picked from commit 9e863fab283eddca9c2a8f9d1ee30f4dc243e314)\n\nCo-authored-by: Steve Dower <steve.dower@python.org>",
23-
"9e863fab283eddca9c2a8f9d1ee30f4dc243e314": "gh-151544: Fixes CVE-2026-12003 by removing the fallback to %VPATH%/Modules/Setup.local for discovering sources in getpath.py (GH-151545)"
24-
},
2526
"CVE-2026-4224": {
2627
"24ce88b285f56ee11626cf5e472af3cd8cc7c621": "[3.12] gh-145986: Avoid unbound C recursion in `conv_content_model` in `pyexpat.c` (CVE 2026-4224) (GH-145987) (#145999)\n\nFix C stack overflow (CVE-2026-4224) when an Expat parser\nwith a registered `ElementDeclHandler` parses inline DTD\ncontaining deeply nested content model.\n\n(cherry picked from commit eb0e8be3a7e11b87d198a2c3af1ed0eccf532768)\n\nCo-authored-by: B\u00e9n\u00e9dikt Tran <10796600+picnixz@users.noreply.github.com>",
2728
"af856a7177326ac25d9f66cc6dd28b554d914fee": "[3.10] gh-145986: Avoid unbound C recursion in `conv_content_model` in `pyexpat.c` (CVE 2026-4224) (GH-145987) (#146002)\n\n* [3.10] gh-145986: Avoid unbound C recursion in `conv_content_model` in `pyexpat.c` (CVE 2026-4224) (GH-145987)\n\nFix C stack overflow (CVE-2026-4224) when an Expat parser\nwith a registered `ElementDeclHandler` parses inline DTD\ncontaining deeply nested content model.\n\n---------\n(cherry picked from commit eb0e8be3a7e11b87d198a2c3af1ed0eccf532768)\n(cherry picked from commit e5caf45faac74b0ed869e3336420cffd3510ce6e)\n\nCo-authored-by: Stan Ulbrych <89152624+StanFromIreland@users.noreply.github.com>\nCo-authored-by: B\u00e9n\u00e9dikt Tran <10796600+picnixz@users.noreply.github.com>\n\n* Update Misc/NEWS.d/next/Security/2026-03-14-17-31-39.gh-issue-145986.ifSSr8.rst\n\n---------\n\nCo-authored-by: B\u00e9n\u00e9dikt Tran <10796600+picnixz@users.noreply.github.com>",

data/fix-commits/expat-ecf459d6.json

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,10 @@
11
{
22
"vcs_url": "https://android.googlesource.com/platform/external/expat",
33
"vulnerabilities": {
4+
"CVE-2026-45186": {
5+
"b7e436e81d947784845284881fc55911ba23ddd5": "Changes: Document upstream CVSS score for CVE-2026-45186 of 2.8.1",
6+
"9bdfbc77e3355405ceefbe59420abed953a5657e": "Merge pull request #1216 from libexpat/attribute-collision-check-dos\n\n[CVE-2026-45186] Prevent attribute collision check DoS"
7+
},
48
"CVE-2026-72522": {
59
"27c6536c2bfa857b6678b1038d14f43fd65a4aa6": "Merge pull request #1296 from libexpat/mozilla-2053153\n\n[CVE-2026-72522] Fix an OOB read and the resulting infinite loop in `*_toUtf16` functions",
610
"8fbfb52fa88e040e8b0b7a9d39f260d6a9e8b6db": "Changes: Document surrogates issue CVE-2026-72522\n\nFor readers new to surrogates in Unicode:\nhttps://en.wikipedia.org/wiki/Universal_Character_Set_characters#Surrogates"
@@ -19,9 +23,6 @@
1923
"3fd4d1c19c30f71979b00d73d367f3d27935fad5": "Merge pull request #1246 from libexpat/introduce-flag-inside-handler\n\n[CVE-2026-50219] Introduce handler call depth tracking",
2024
"f17ca46befb59098da339ed6d2438de3bdece8b5": "Changes: Document CVE-2026-50219"
2125
},
22-
"CVE-2026-45186": {
23-
"9bdfbc77e3355405ceefbe59420abed953a5657e": "Merge pull request #1216 from libexpat/attribute-collision-check-dos\n\n[CVE-2026-45186] Prevent attribute collision check DoS"
24-
},
2526
"CVE-2026-41080": {
2627
"ed80eaea0ce7179b56713fb22fe933b993aee814": "Merge pull request #1183 from libexpat/issue-47-improve-protection-against-hash-flooding\n\n[CVE-2026-41080] Improve protection against hash flooding (fixes #47)",
2728
"4ba09dc471b39a78d77e5179d0243186c0c4ff7a": "Changes: Document CVE-2026-41080 and better protection against hash flooding"

0 commit comments

Comments
 (0)